Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
2 changes: 2 additions & 0 deletions .github/dependabot.yml

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

we should probably get rid of that as we are using renovate

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

can you send this as a follow-up? trying to keep these bot PRs focused

Original file line number Diff line number Diff line change
Expand Up @@ -5,6 +5,8 @@ version: 2
updates:
- package-ecosystem: github-actions
directory: /
cooldown:
default-days: 7
groups:
github-actions:
patterns:
Expand Down
2 changes: 2 additions & 0 deletions .github/workflows/add-to-project.yml
Original file line number Diff line number Diff line change
Expand Up @@ -21,6 +21,8 @@ jobs:
with:
client-id: ${{ vars.OTELBOT_PYTHON_CLIENT_ID }}
private-key: ${{ secrets.OTELBOT_PYTHON_PRIVATE_KEY }}
permission-organization-projects: write
permission-pull-requests: read

- uses: actions/add-to-project@244f685bbc3b7adfa8466e08b698b5577571133e # v1.0.2
with:
Expand Down
1 change: 1 addition & 0 deletions .github/workflows/backport.yml
Original file line number Diff line number Diff line change
Expand Up @@ -36,6 +36,7 @@ jobs:
with:
client-id: ${{ vars.OTELBOT_CLIENT_ID }}
private-key: ${{ secrets.OTELBOT_PRIVATE_KEY }}
permission-pull-requests: write

- name: Create pull request
env:
Expand Down
12 changes: 8 additions & 4 deletions .github/workflows/changelog.yml
Original file line number Diff line number Diff line change
Expand Up @@ -21,6 +21,8 @@ jobs:
github.event_name != 'merge_group' &&
!contains(github.event.pull_request.labels.*.name, 'Skip Changelog')
&& github.actor != 'otelbot[bot]'
env:
BASE_REF: ${{ github.base_ref }}

steps:
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
Expand All @@ -29,7 +31,7 @@ jobs:
fetch-depth: 0

- name: Fetch base branch
run: git fetch origin ${{ github.base_ref }} --depth=1
run: git fetch origin "$BASE_REF" --depth=1

- name: Ensure no direct changes to CHANGELOG.md
run: |
Expand All @@ -47,11 +49,13 @@ jobs:
run: pip install towncrier==25.8.0

- name: Check for changelog fragment
env:
PR_NUMBER: ${{ github.event.pull_request.number }}
run: |
if ! towncrier check --compare-with origin/${{ github.base_ref }}; then
if ! towncrier check --compare-with "origin/$BASE_REF"; then
echo ""
echo "No changelog fragment found for this PR."
echo "Add a file named .changelog/${{ github.event.pull_request.number }}.<type>"
echo "Add a file named .changelog/$PR_NUMBER.<type>"
echo "where <type> is one of: added, changed, deprecated, removed, fixed"
echo "See CONTRIBUTING.md for details."
echo ""
Expand All @@ -63,7 +67,7 @@ jobs:
env:
PR_NUMBER: ${{ github.event.pull_request.number }}
run: |
fragments=$(git diff --diff-filter=A --name-only origin/${{ github.base_ref }} -- '.changelog/*' | grep -v '/\.gitignore$' || true)
fragments=$(git diff --diff-filter=A --name-only "origin/$BASE_REF" -- '.changelog/*' | grep -v '/\.gitignore$' || true)
[ -z "$fragments" ] && exit 0
invalid=()
while IFS= read -r f; do
Expand Down
12 changes: 10 additions & 2 deletions .github/workflows/check-links.yml
Original file line number Diff line number Diff line change
Expand Up @@ -50,29 +50,37 @@ jobs:
files: |
**/*.md
**/*.rst
json: true
escape_json: false

- name: Install markdown-link-check
if: steps.changed-files.outputs.any_changed == 'true'
run: npm install -g markdown-link-check@v3.12.2

- name: Check links on push to main
if: steps.changed-files.outputs.any_changed == 'true' && github.event_name == 'push'
env:
CHANGED_FILES: ${{ steps.changed-files.outputs.all_changed_files }}
run: |
mapfile -t changed_files < <(jq -r '.[]' <<< "$CHANGED_FILES")
markdown-link-check \
--verbose \
--config .github/workflows/check_links_config.json \
${{ steps.changed-files.outputs.all_changed_files }} \
"${changed_files[@]}" \
|| { echo "Check that anchor links are lowercase"; exit 1; }

- name: Check new links only on pull requests and merge groups
if: steps.changed-files.outputs.any_changed == 'true' && (github.event_name == 'pull_request' || github.event_name == 'merge_group')
env:
CHANGED_FILES: ${{ steps.changed-files.outputs.all_changed_files }}
run: |
mapfile -t changed_files < <(jq -r '.[]' <<< "$CHANGED_FILES")
# Extract URLs only from added lines in the diff to avoid
# rate limiting when checking all links in large files like
# CHANGELOG.md. Only new/changed links are checked on PRs;
# pushes to main still check all links in changed files.
git diff "$DIFF_RANGE" -- \
${{ steps.changed-files.outputs.all_changed_files }} \
"${changed_files[@]}" \
| grep '^+' | grep -v '^+++' \
| grep -oP 'https?://[^\s\)\]\"'"'"'`>]+' \
| sort -u > /tmp/new_links.txt
Expand Down
6 changes: 3 additions & 3 deletions .github/workflows/ci.yml
Original file line number Diff line number Diff line change
Expand Up @@ -19,11 +19,11 @@ concurrency:

jobs:
misc:
uses: ./.github/workflows/misc.yml
uses: $/.github/workflows/misc.yml
lint:
uses: ./.github/workflows/lint.yml
uses: $/.github/workflows/lint.yml
tests:
uses: ./.github/workflows/test.yml
uses: $/.github/workflows/test.yml
Comment thread
trask marked this conversation as resolved.
contrib:
uses: open-telemetry/opentelemetry-python-contrib/.github/workflows/core_contrib_test.yml@main
with:
Expand Down
7 changes: 5 additions & 2 deletions .github/workflows/prepare-patch-release.yml
Original file line number Diff line number Diff line change
Expand Up @@ -71,6 +71,7 @@ jobs:
with:
client-id: ${{ vars.OTELBOT_CLIENT_ID }}
private-key: ${{ secrets.OTELBOT_PRIVATE_KEY }}
permission-pull-requests: write

- name: Create pull request
id: create_pr
Expand All @@ -93,8 +94,9 @@ jobs:
if: steps.create_pr.outputs.pr_url != ''
env:
GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
PR_URL: ${{ steps.create_pr.outputs.pr_url }}
run: |
gh pr edit ${{ steps.create_pr.outputs.pr_url }} --add-label "prepare-release"
gh pr edit "$PR_URL" --add-label "prepare-release"

- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
Expand Down Expand Up @@ -132,5 +134,6 @@ jobs:
if: steps.backport_pr.outputs.pr_url != ''
env:
GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
PR_URL: ${{ steps.backport_pr.outputs.pr_url }}
run: |
gh pr edit ${{ steps.backport_pr.outputs.pr_url }} --add-label "Skip Changelog"
gh pr edit "$PR_URL" --add-label "Skip Changelog"
8 changes: 6 additions & 2 deletions .github/workflows/prepare-release-branch.yml
Original file line number Diff line number Diff line change
Expand Up @@ -99,6 +99,7 @@ jobs:
with:
client-id: ${{ vars.OTELBOT_CLIENT_ID }}
private-key: ${{ secrets.OTELBOT_PRIVATE_KEY }}
permission-pull-requests: write

- name: Create pull request against the release branch
id: create_release_branch_pr
Expand All @@ -121,8 +122,9 @@ jobs:
if: steps.create_release_branch_pr.outputs.pr_url != ''
env:
GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
PR_URL: ${{ steps.create_release_branch_pr.outputs.pr_url }}
run: |
gh pr edit ${{ steps.create_release_branch_pr.outputs.pr_url }} --add-label "prepare-release"
gh pr edit "$PR_URL" --add-label "prepare-release"

create-pull-request-against-main:
permissions:
Expand Down Expand Up @@ -196,6 +198,7 @@ jobs:
with:
client-id: ${{ vars.OTELBOT_CLIENT_ID }}
private-key: ${{ secrets.OTELBOT_PRIVATE_KEY }}
permission-pull-requests: write

- name: Create pull request against main
id: create_main_pr
Expand All @@ -219,5 +222,6 @@ jobs:
if: steps.create_main_pr.outputs.pr_url != ''
env:
GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
PR_URL: ${{ steps.create_main_pr.outputs.pr_url }}
run: |
gh pr edit ${{ steps.create_main_pr.outputs.pr_url }} --add-label "prepare-release" --add-label "Skip Changelog"
gh pr edit "$PR_URL" --add-label "prepare-release" --add-label "Skip Changelog"
6 changes: 3 additions & 3 deletions .github/workflows/templates/ci.yml.j2
Original file line number Diff line number Diff line change
Expand Up @@ -19,11 +19,11 @@ concurrency:

jobs:
misc:
uses: ./.github/workflows/misc.yml
uses: $/.github/workflows/misc.yml
lint:
uses: ./.github/workflows/lint.yml
uses: $/.github/workflows/lint.yml
tests:
uses: ./.github/workflows/test.yml
uses: $/.github/workflows/test.yml
Comment thread
trask marked this conversation as resolved.
contrib:
uses: open-telemetry/opentelemetry-python-contrib/.github/workflows/core_contrib_test.yml@main
with:
Expand Down
20 changes: 20 additions & 0 deletions .github/workflows/zizmor.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,20 @@
name: Zizmor

on:
push:
branches:
- main
- release/*
pull_request:
schedule:
- cron: '9 12 * * 4' # weekly at 12:09 UTC on Thursday
workflow_dispatch:

permissions: {}

jobs:
zizmor:
permissions:
contents: read # for actions/checkout
security-events: write # for zizmor to upload SARIF results
uses: open-telemetry/shared-workflows/.github/workflows/zizmor.yml@d9b812f9924a121c6a8276ea2f9e6f5b622cdd4d # v0.10.0
20 changes: 20 additions & 0 deletions .github/zizmor.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,20 @@
rules:
adhoc-packages:
ignore:
# This isolated link-check job pins the CLI to v3.12.2.
- check-links.yml:56
dangerous-triggers:
ignore:
# The project-board job uses PR metadata but never checks out or runs PR code.
- add-to-project.yml:3
unpinned-uses:
config:
policies:
"*": hash-pin
# Contrib integration tests intentionally follow the current workflow on main.
"open-telemetry/opentelemetry-python-contrib/.github/workflows/core_contrib_test.yml": ref-pin
use-trusted-publishing:
ignore:
# TestPyPI and PyPI publishing use existing tokens until trusted publishers are configured.
- release.yml:97
- release.yml:104
Loading